Skip to content

Evidence request lists

Cayman Islands Data Protection Act 2017 (DPA)

Evidence request list. 22 controls, 22 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Cayman DPA: Controller Obligations and Breach

CAYDPA-s16
Personal Data Breach Notification (s.16)

s.16: where a personal data breach occurs, the data controller must, without undue delay and in any event within 5 days of becoming aware, notify the Ombudsman and any affected data subject.

Artefacts an auditor will ask for
  • breach detection and assessment process
  • records of notification to the Ombudsman and affected data subjects within the statutory time
  • breach register
Where this commonly fails
  • breaches not notified to the Ombudsman
  • affected individuals not notified
  • notification beyond the statutory deadline

Cayman DPA: Data Protection Principles (Schedule 1)

CAYDPA-P1
First Principle - Fair and Lawful Processing

Schedule 1, First Principle: personal data must be processed fairly and lawfully, and only if at least one Schedule 2 condition (and, for sensitive data, a Schedule 3 condition) is met, with specified information provided to the data subject.

Artefacts an auditor will ask for
  • identified Schedule 2 (and Schedule 3 for sensitive) condition for each processing
  • privacy/fair-processing notices providing the specified information
Where this commonly fails
  • processing without a Schedule 2/3 condition
  • no fair-processing notice
CAYDPA-P2
Second Principle - Purpose Limitation

Schedule 1, Second Principle: personal data must be obtained only for one or more specified lawful purposes and not further processed in a manner incompatible with those purposes.

Artefacts an auditor will ask for
  • evidence the principle is met in processing operations
  • records/policies demonstrating compliance
  • data protection impact / processing records
Where this commonly fails
  • principle not demonstrably applied
  • no records evidencing compliance
CAYDPA-P3
Third Principle - Adequate, Relevant and Not Excessive

Schedule 1, Third Principle: personal data must be adequate, relevant and not excessive in relation to the purpose(s) for which they are processed (data minimisation).

Artefacts an auditor will ask for
  • evidence the principle is met in processing operations
  • records/policies demonstrating compliance
  • data protection impact / processing records
Where this commonly fails
  • principle not demonstrably applied
  • no records evidencing compliance
CAYDPA-P4
Fourth Principle - Accuracy

Schedule 1, Fourth Principle: personal data must be accurate and, where necessary, kept up to date.

Artefacts an auditor will ask for
  • evidence the principle is met in processing operations
  • records/policies demonstrating compliance
  • data protection impact / processing records
Where this commonly fails
  • principle not demonstrably applied
  • no records evidencing compliance
CAYDPA-P5
Fifth Principle - Storage Limitation

Schedule 1, Fifth Principle: personal data must not be kept for longer than is necessary for the purpose(s) for which they are processed.

Artefacts an auditor will ask for
  • evidence the principle is met in processing operations
  • records/policies demonstrating compliance
  • data protection impact / processing records
Where this commonly fails
  • principle not demonstrably applied
  • no records evidencing compliance
CAYDPA-P6
Sixth Principle - Rights of Data Subjects

Schedule 1, Sixth Principle: personal data must be processed in accordance with the rights of data subjects under the Act.

Artefacts an auditor will ask for
  • evidence the principle is met in processing operations
  • records/policies demonstrating compliance
  • data protection impact / processing records
Where this commonly fails
  • principle not demonstrably applied
  • no records evidencing compliance
CAYDPA-P7
Seventh Principle - Security

Schedule 1, Seventh Principle: appropriate technical and organisational measures must be taken against unauthorised or unlawful processing and against accidental loss, destruction of, or damage to personal data; processors must provide sufficient guarantees.

Artefacts an auditor will ask for
  • appropriate technical and organisational security measures proportionate to risk
  • contracts requiring processors to provide sufficient security guarantees
Where this commonly fails
  • security measures not proportionate to risk
  • processor security guarantees not obtained
CAYDPA-P8
Eighth Principle - International Transfer

Schedule 1, Eighth Principle: personal data must not be transferred to a country or territory unless that country or territory ensures an adequate level of protection, subject to the Schedule 4 exceptions.

Artefacts an auditor will ask for
  • adequacy assessment of destination country/territory
  • reliance on a Schedule 4 transfer exception where applicable
Where this commonly fails
  • transfer without adequacy or a Schedule 4 basis

Cayman DPA: Enforcement and the Ombudsman

CAYDPA-s43
Complaints to the Ombudsman (s.43)

s.43: a person may complain to the Ombudsman that a data controller has contravened or is contravening the Act; the Ombudsman may investigate.

Artefacts an auditor will ask for
  • process for responding to and cooperating with an Ombudsman complaint or investigation
Where this commonly fails
  • no process to respond to an Ombudsman complaint
CAYDPA-s47
Right to Seek Judicial Review (s.47)

s.47: a person aggrieved by an order, determination or decision of the Ombudsman may apply to the Grand Court for judicial review.

Artefacts an auditor will ask for
  • awareness of judicial-review rights and process
CAYDPA-s55
Power of the Ombudsman to Impose Monetary Penalty (s.55)

s.55: the Ombudsman may impose a monetary penalty order on a data controller or processor for serious contraventions of the Act.

Artefacts an auditor will ask for
  • awareness of monetary-penalty exposure
  • process for responding to a monetary penalty order
Where this commonly fails
  • no process for responding to enforcement action

Cayman DPA: Exemptions

CAYDPA-s18
National Security Exemption (s.18)

s.18: personal data are exempt from the provisions of the Act where the exemption is required for the purpose of safeguarding national security.

Artefacts an auditor will ask for
  • documented basis for any national-security exemption relied upon
Where this commonly fails
  • exemption relied on without proper basis
CAYDPA-s31
Exemptions by Regulations (s.31)

s.31: further exemptions from the Act may be provided for by regulations; reliance on any such exemption must meet its conditions.

Artefacts an auditor will ask for
  • analysis of any regulatory exemption relied upon and its conditions
Where this commonly fails
  • exemption misapplied

Cayman DPA: Rights of Data Subjects

CAYDPA-s10
Right to Stop Processing Likely to Cause Damage or Distress (s.10)

s.10: a data subject may by notice require a data controller to cease, or not begin, processing that is causing or likely to cause unwarranted substantial damage or distress.

Artefacts an auditor will ask for
  • process to receive and respond to s.10 notices
Where this commonly fails
  • s.10 notices not actioned
CAYDPA-s11
Right to Stop Processing for Direct Marketing (s.11)

s.11: a data subject may by notice require a data controller to cease processing personal data for the purposes of direct marketing.

Artefacts an auditor will ask for
  • marketing suppression list and opt-out mechanism
Where this commonly fails
  • marketing continued after opt-out
CAYDPA-s12
Rights in Relation to Automated Decision-Making (s.12)

s.12: a data subject may require that decisions significantly affecting them are not based solely on automated processing, and is entitled to information about the logic.

Artefacts an auditor will ask for
  • identification of solely-automated decisions
  • mechanism to require human involvement and explain the logic
Where this commonly fails
  • solely-automated significant decisions without safeguards
CAYDPA-s14
Rectification, Blocking, Erasure or Destruction (s.14)

s.14: a data subject may apply to the court for an order to rectify, block, erase or destroy inaccurate personal data (and related expressions of opinion).

Artefacts an auditor will ask for
  • process to rectify, block, erase or destroy inaccurate data
  • records of corrections and notifications to third parties
Where this commonly fails
  • inaccurate data not corrected on valid request
CAYDPA-s8
Fundamental Rights of Access to Personal Data (s.8)

s.8: a data subject is entitled, on request, to be informed whether personal data are processed and to be given a description of and access to the data, the purposes, recipients and the source.

Artefacts an auditor will ask for
  • subject-access-request handling process and records
  • responses within the statutory timeframe
Where this commonly fails
  • access requests not honoured or late

Cayman DPA: Schedules - Conditions and Transfers

CAYDPA-Sch2
Schedule 2 - Conditions for Processing (General Personal Data)

Schedule 2: at least one condition must be met for processing of general personal data to satisfy the First Principle (e.g. consent, contract, legal obligation, vital interests, public functions, legitimate interests).

Artefacts an auditor will ask for
  • documented Schedule 2 condition for each general-data processing activity
Where this commonly fails
  • no Schedule 2 condition identified
CAYDPA-Sch3
Schedule 3 - Conditions for Processing Sensitive Personal Data

Schedule 3: additional conditions that must be met (in addition to a Schedule 2 condition) to process sensitive personal data.

Artefacts an auditor will ask for
  • documented Schedule 3 condition for each sensitive-data processing activity
Where this commonly fails
  • sensitive data processed without a Schedule 3 condition
CAYDPA-Sch4
Schedule 4 - Transfers to Which the Eighth Principle Does Not Apply

Schedule 4: the circumstances in which a transfer of personal data to a country without adequate protection is nonetheless permitted (e.g. consent, contract, substantial public interest, legal proceedings).

Artefacts an auditor will ask for
  • documented Schedule 4 basis for any transfer to a non-adequate country
Where this commonly fails
  • transfer to non-adequate country without a Schedule 4 basis
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Cayman Islands Data Protection Act 2017 (DPA) framework page.